MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cbd57b480505947bde04f95df8639eddfdfde609b23ba4669b7cdee6ffa77d19. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: cbd57b480505947bde04f95df8639eddfdfde609b23ba4669b7cdee6ffa77d19
SHA3-384 hash: eb8ecf8473b7b913720d34f49020b83612203185838aec695d20e5ac7fc674eef44ca272f2ad5d91b448d682521814fb
SHA1 hash: 57e1d0b782c174059611aae4a6d195c1edce5536
MD5 hash: 2cacbcdfeb26d1725d80422e253a2fc8
humanhash: seven-oranges-one-twenty
File name:cbd57b480505947bde04f95df8639eddfdfde609b23ba4669b7cdee6ffa77d19
Download: download sample
Signature CoinMiner
File size:1'796'112 bytes
First seen:2026-07-27 15:55:58 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 49152:BTqdFctG2Czd5CSZSX+TEYVamMld+DQa6UGpNEQcjCbuvqLWu4a:sctG2aCSHAVmMldmQjpNEH+buaW2
TLSH T1BB853354E38C4944F9E349E117A1AEFF8DA6B14CC06E1B34EB3E91C446B5F250FB48A6
telfhash t10bb001534b08a69102ab8daa91afe511c1e042a6242e4687048d1a09269d236c2a649b
Magika elf
Reporter Hassan_Pouladi
Tags:elf UPX
File size (compressed) :1'796'112 bytes
File size (de-compressed) :5'107'292 bytes
Format:linux/i386
Unpacked file: a516213a66bbab81d9d90526a7cd9f9179499b1f625c44a4b94cb96058120360

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
CA CA
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Creating a file
Sends data to a server
Collects information on the RAM
Connection attempt
Receives data from a server
Kills processes
Changes access rights for a written file
Changes the time when the file was created, accessed, or modified
Runs as daemon
Collects information on the CPU
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
coinminer packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
1
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2026-07-19T01:15:00Z UTC
Last seen:
2026-07-28T19:31:00Z UTC
Hits:
~10000
Status:
terminated
Behavior Graph:
%3 guuid=9625742a-1f00-0000-ea6c-91b891070000 pid=1937 /usr/bin/sudo guuid=1157472d-1f00-0000-ea6c-91b896070000 pid=1942 /tmp/sample.bin write-file guuid=9625742a-1f00-0000-ea6c-91b891070000 pid=1937->guuid=1157472d-1f00-0000-ea6c-91b896070000 pid=1942 execve guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041 /tmp/sample.bin net zombie guuid=1157472d-1f00-0000-ea6c-91b896070000 pid=1942->guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041 clone caec5668-d34a-5eb7-86d9-4f5a59806182 45.148.10.144:21370 guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->caec5668-d34a-5eb7-86d9-4f5a59806182 con d74b69c6-5fab-527c-9fe4-bf73738bd51d 45.148.10.112:21370 guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->d74b69c6-5fab-527c-9fe4-bf73738bd51d con 5f6004ab-135d-5863-8d6f-a6f76ba0720b 45.148.10.68:21370 guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->5f6004ab-135d-5863-8d6f-a6f76ba0720b con 77cad3d3-56c7-572a-ac52-ee77e47bf870 45.148.10.113:2137 guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->77cad3d3-56c7-572a-ac52-ee77e47bf870 con 0f31b1cb-e863-5dc9-8beb-7665b59ed1a9 95.215.19.53:853 guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->0f31b1cb-e863-5dc9-8beb-7665b59ed1a9 con 14ac75f0-edad-5de2-b6fb-37afde7f0bf7 45.148.10.208:21370 guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->14ac75f0-edad-5de2-b6fb-37afde7f0bf7 con guuid=bb24616f-1f00-0000-ea6c-91b801080000 pid=2049 /usr/bin/dash guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->guuid=bb24616f-1f00-0000-ea6c-91b801080000 pid=2049 execve guuid=0b5bcb6f-1f00-0000-ea6c-91b805080000 pid=2053 /tmp/sample.bin guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->guuid=0b5bcb6f-1f00-0000-ea6c-91b805080000 pid=2053 clone guuid=33888873-1f00-0000-ea6c-91b80f080000 pid=2063 /usr/bin/dash guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->guuid=33888873-1f00-0000-ea6c-91b80f080000 pid=2063 execve guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2122 /tmp/sample.bin bpf-socket-filter net net-scan send-data write-config zombie guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2122 clone guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2151 /tmp/sample.bin guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2041->guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2151 clone guuid=1731a86f-1f00-0000-ea6c-91b803080000 pid=2051 /usr/bin/dash guuid=bb24616f-1f00-0000-ea6c-91b801080000 pid=2049->guuid=1731a86f-1f00-0000-ea6c-91b803080000 pid=2051 clone guuid=272eae6f-1f00-0000-ea6c-91b804080000 pid=2052 /usr/bin/dash guuid=bb24616f-1f00-0000-ea6c-91b801080000 pid=2049->guuid=272eae6f-1f00-0000-ea6c-91b804080000 pid=2052 clone guuid=d7edd46f-1f00-0000-ea6c-91b806080000 pid=2054 /tmp/sample.bin zombie guuid=0b5bcb6f-1f00-0000-ea6c-91b805080000 pid=2053->guuid=d7edd46f-1f00-0000-ea6c-91b806080000 pid=2054 clone guuid=449cd373-1f00-0000-ea6c-91b811080000 pid=2065 /usr/sbin/xtables-nft-multi guuid=33888873-1f00-0000-ea6c-91b80f080000 pid=2063->guuid=449cd373-1f00-0000-ea6c-91b811080000 pid=2065 execve guuid=0179127f-1f00-0000-ea6c-91b82f080000 pid=2095 /usr/sbin/xtables-nft-multi guuid=33888873-1f00-0000-ea6c-91b80f080000 pid=2063->guuid=0179127f-1f00-0000-ea6c-91b82f080000 pid=2095 execve guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2122|network network activity to 2060 IP addresses review logs to see them all guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2122->guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2122|network network guuid=98da0396-1f00-0000-ea6c-91b85d080000 pid=2141 /usr/bin/dash guuid=2eb2be6b-1f00-0000-ea6c-91b8f9070000 pid=2122->guuid=98da0396-1f00-0000-ea6c-91b85d080000 pid=2141 execve guuid=82b34096-1f00-0000-ea6c-91b85e080000 pid=2142 /usr/sbin/xtables-nft-multi guuid=98da0396-1f00-0000-ea6c-91b85d080000 pid=2141->guuid=82b34096-1f00-0000-ea6c-91b85e080000 pid=2142 execve guuid=cec9cc96-1f00-0000-ea6c-91b860080000 pid=2144 /usr/sbin/xtables-nft-multi guuid=98da0396-1f00-0000-ea6c-91b85d080000 pid=2141->guuid=cec9cc96-1f00-0000-ea6c-91b860080000 pid=2144 execve guuid=82ef3697-1f00-0000-ea6c-91b862080000 pid=2146 /usr/sbin/xtables-nft-multi guuid=98da0396-1f00-0000-ea6c-91b85d080000 pid=2141->guuid=82ef3697-1f00-0000-ea6c-91b862080000 pid=2146 execve guuid=fcbbd797-1f00-0000-ea6c-91b863080000 pid=2147 /usr/sbin/xtables-nft-multi guuid=98da0396-1f00-0000-ea6c-91b85d080000 pid=2141->guuid=fcbbd797-1f00-0000-ea6c-91b863080000 pid=2147 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-19 06:04:10 UTC
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
antivm command_and_control defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
Reads network interface configuration
Creates Raw socket
Flushes firewall rules
Outbound SSH connection to public host
Unexpected DNS network traffic destination
Contacts a large (228508) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

CoinMiner

elf cbd57b480505947bde04f95df8639eddfdfde609b23ba4669b7cdee6ffa77d19

(this sample)

Comments